CVE Vulnerabilities

CVE-2012-4481

Published: May 02, 2013 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.

Affected Software

Name Vendor Start Version End Version
Ruby Ruby-lang 1.8.7 (including) 1.8.7 (including)
Red Hat Enterprise Linux 5 RedHat ruby-0:1.8.5-27.el5 *
Red Hat Enterprise Linux 6 RedHat ruby-0:1.8.7.352-10.el6_4 *
Ruby1.8 Ubuntu hardy *
Ruby1.8 Ubuntu lucid *
Ruby1.8 Ubuntu natty *
Ruby1.8 Ubuntu oneiric *
Ruby1.8 Ubuntu precise *
Ruby1.8 Ubuntu quantal *
Ruby1.8 Ubuntu upstream *
Ruby1.9 Ubuntu hardy *

References